AI Regulation in the European Union
The European Union has enacted the most comprehensive AI regulatory framework in the world. The EU AI Act — effective August 2024, with enforcement phasing through 2026 and 2027 — introduces risk-based obligations for AI developers and deployers across four tiers: prohibited uses, high-risk systems with strict conformity requirements, limited-risk systems with transparency obligations, and minimal-risk AI with no specific mandates.
Alongside the AI Act, organizations deploying AI in EU markets must navigate a layered stack of intersecting regulations. GDPR governs personal data used to train and operate AI systems. The Digital Operational Resilience Act (DORA) sets requirements for AI in financial services. The Data Act, Digital Services Act, and Cyber Resilience Act each add obligations relevant to specific AI use cases. The EU AI Office, established in 2024, is the central authority responsible for regulating general-purpose AI models with systemic risk.
For compliance teams, the EU's approach means that no single framework is sufficient. A high-risk AI system in healthcare or hiring must satisfy the AI Act's conformity assessment requirements, maintain GDPR-compliant data practices, and meet sector-specific rules simultaneously. Organizations using AI in critical infrastructure, biometrics, or access to essential services face the most demanding compliance burden.
Key themes
- 1.Risk-tiered obligations — prohibited, high-risk, limited risk, minimal risk
- 2.Prohibited AI practices (social scoring, real-time biometrics in public spaces)
- 3.General-purpose AI model governance via the EU AI Office
- 4.Intersection with GDPR, DSA, DORA, and the Data Act
Regulatory frameworks and guidance(15)
European Commission Enforcement Powers for Advanced AI Models under the AI Act
This framework describes the European Commission's active enforcement powers over providers of the most advanced general-purpose AI models under the EU AI Act. It applies to providers whose models meet the high-capability thresholds defined in the Act, regardless of where those providers are incorporated. Covered providers may face information requests, mandatory model access for evaluation, required risk mitigation measures, and financial penalties of up to 3 percent of global annual turnover.
EU Action Plan on Cybersecurity and Artificial Intelligence
The European Commission's Action Plan on Cybersecurity and Artificial Intelligence establishes a coordinated approach to securing AI systems deployed across the EU. It applies to developers and deployers of AI models subject to the EU AI Act, particularly those operating advanced or high-risk systems. The plan creates dedicated evaluation infrastructure, including a secure testing platform and an EU-level evaluation capability for advanced AI models.
Regulation (EU) 2026/1744: AI Act Omnibus Amendment (High-Risk Deadline Deferral)
Regulation (EU) 2026/1744 is the AI Act Omnibus amendment that pushed back the EU AI Act's high-risk compliance deadlines. Stand-alone Annex III high-risk systems now have until 2 December 2027, moved from 2 August 2026. High-risk AI embedded in products regulated under existing EU law gets a longer runway, to 2 August 2028. The obligations already in force are untouched: GPAI model duties have applied since August 2025, and the prohibited-practices list and AI literacy requirement have applied since February 2026.
EU AI Act Harmonised Standard prEN 18286, Quality Management Systems for AI
prEN 18286 is a draft harmonised standard under public enquiry that supports conformity with the EU AI Act, specifically in the area of quality management systems for AI. It applies to organisations developing or deploying AI systems that fall within the Act's scope and seek to demonstrate regulatory conformity through standardised evidence. Achieving conformity with a harmonised standard creates a presumption of conformity with the corresponding AI Act requirements it covers.
EU AI Act: AI Literacy and Prohibited AI Systems Provisions (Applicable 2 February 2026)
The EU AI Act's first major compliance deadline takes effect on 2 February 2026, requiring all organizations that develop or deploy AI within the EU to establish AI literacy measures for their workforce. As of this date, the Act's prohibitions on AI systems deemed to pose unacceptable risks also become enforceable. Organizations must have ceased operation of any prohibited AI practices and demonstrated adequate staff competency with AI systems by this date.
EU AI Liability Directive
A proposed EU directive that would have adapted civil liability rules to apply to AI systems, enabling individuals harmed by AI to obtain compensation by lowering evidentiary burdens through disclosure and causation presumptions. The proposal was formally withdrawn in early 2025 following failure to reach political agreement.
AI Omnibus Regulation (EU AI Act Extension)
The AI Omnibus is a binding EU regulation that entered into force on 27 July 2026, extending the oversight powers of the AI Office established under the EU AI Act. It applies to providers and deployers of general-purpose AI systems, as well as AI systems embedded within large online platforms and search engines. Covered organizations must maintain robust model governance, conduct provider due diligence, and respond to compliance evidence requests from the AI Office.
EU Code of Practice on Transparency of AI-Generated Content
The European Commission published this voluntary Code of Practice to support compliance with Article 50 of the EU AI Act, which mandates transparency obligations for AI-generated content. It applies to providers and deployers of generative AI systems operating in the EU market. The Code establishes practical standards for content labeling, provenance controls, and disclosure workflows.
EU Cyber Resilience Act
The EU Cyber Resilience Act establishes mandatory cybersecurity requirements for products with digital elements placed on the EU market, including hardware and software incorporating AI components, covering the entire product lifecycle from design through end-of-life.
EU Data Act
The EU Data Act establishes harmonised rules on access to and use of data generated by connected products and related services across the EU, addressing both personal and non-personal data. It creates new obligations for data holders to share data with users and third parties, and sets conditions for public sector bodies to access privately held data in exceptional circumstances.
EU Data Governance Act
The EU Data Governance Act establishes a regulatory framework for data intermediaries, data altruism organisations, and the re-use of public sector data protected by third-party rights. It creates new governance structures to facilitate trusted data sharing across sectors and member states, supporting the broader European Data Strategy.
EU Proposal for a Regulation for the Digital Networks Act (DNA)
The Digital Networks Act is a legislative proposal introduced by the European Commission on January 21, 2026, addressing digital infrastructure and aspects of AI governance within the European Union. It is currently subject to co-legislative review and negotiation by the European Parliament and the Council of the EU. The proposal is expected to impose obligations on entities operating or deploying digital network infrastructure, including those integrating AI-driven network management systems.
EU Digital Operational Resilience Act
The EU Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, establishes a comprehensive ICT risk management, incident reporting, operational resilience testing, and third-party risk oversight framework for EU financial entities, with direct implications for AI systems deployed in financial services and the technology providers that supply them.
EU Digital Services Act, AI and Algorithmic Accountability Provisions
The Digital Services Act imposes transparency, accountability, and risk-management obligations on online intermediaries with respect to algorithmic recommender systems, targeted advertising, and systemic risks. Obligations scale with platform size, with the most stringent requirements applying to VLOPs and VLOSEs.
EU General-Purpose AI Model Training Data Public Summary Template
The European Commission published a standardized template for providers of general-purpose AI models to use when publicly disclosing summaries of their training data. It supports compliance with the transparency obligations for general-purpose AI models established under the EU AI Act. Providers are expected to follow the template structure when meeting their disclosure requirements under that regulation.
